CVE-2016-7154: Use After Free
Published Sep 21, 2016
·Updated
Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.
Affected Software
5 affected components
XEN Xen=4.4.0
XEN Xen=4.4.1
XEN Xen=4.4.2
XEN Xen=4.4.3
XEN Xen=4.4.4
Remediation
Patch Available
Patch Available
Event History
Sep 21, 2016
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7154?
CVE-2016-7154 is rated as high severity due to its potential to cause a denial of service or arbitrary code execution.
2
How do I fix CVE-2016-7154?
To fix CVE-2016-7154, you should update your Xen hypervisor to version 4.4.5 or later.
3
Who is affected by CVE-2016-7154?
CVE-2016-7154 affects local guest OS administrators running Xen versions 4.4.0 through 4.4.4.
4
What type of attack does CVE-2016-7154 enable?
CVE-2016-7154 enables local guest OS administrators to potentially crash the host or execute arbitrary code.
5
What software versions are vulnerable to CVE-2016-7154?
Xen versions 4.4.0, 4.4.1, 4.4.2, 4.4.3, and 4.4.4 are vulnerable to CVE-2016-7154.